Skip to content

Directory

Connect your identity provider for single sign-on, and verify the email domains its people sign in with.

Updated View as Markdown

In IAM > Directory, you connect your organization’s identity provider, such as Okta, Microsoft Entra ID or Google Workspace, over OIDC or SAML 2.0, and verify the email domains its people use. People with an email address in a verified domain can sign in with SSO, and SCIM provisioning can create and manage them.

Identity providers are managed in the console.

Verified domains

A verified domain is an email domain your organization proved it owns by publishing a DNS TXT record. You list one or more email domains when you add an identity provider, and they’re verified together.

A verified domain:

  • Lets people with an email address in it sign in through the identity provider. Nobody can sign in through a provider until its domains are verified.
  • Lets SCIM provision people with an email address in it. SCIM refuses everyone else.
  • While SCIM is on, can’t be invited: invitations to email addresses in it return 409 with managed_by_scim.

An email address in a subdomain of a verified domain counts too: verifying example.com covers ada@eu.example.com.

The Directory page shows each provider’s status: Verified or Domain not verified. The API’s GetScimConfiguration returns your organization’s verified domains in verifiedDomains.

Permissions

Action Allows Managed policies
ssoProviders.list See identity providers, their domains and verification status ReadOnlyAccess, IAMFullAccess
ssoProviders.create Add identity providers IAMFullAccess
ssoProviders.verifyDomain Verify a provider’s domains IAMFullAccess
ssoProviders.update Change a provider’s group mapping IAMFullAccess
ssoProviders.delete Delete identity providers IAMFullAccess

ssoProviders.update, ssoProviders.verifyDomain and ssoProviders.delete can be scoped to one provider by its resource name, ezgh::org_…:sso_….

Add an identity provider

  1. Open IAM > Directory and select Add identity provider.
  2. Choose the Protocol, OIDC or SAML 2.0, and enter the Email domains, separated by commas: example.com, example.org.
  3. Enter your identity provider’s details:
    • OIDC: the Issuer URL, Client ID and Client secret. Authorization endpoint is optional; set it only if browsers reach your provider at a different address than the issuer.
    • SAML 2.0: the SSO URL and the IdP metadata XML.
  4. Optionally, map groups at your identity provider to groups in your organization. See Group mapping.
  5. Review, then select Add provider.

The console then shows what to configure at your identity provider: the Redirect URI for OIDC, or the Entity ID (audience), ACS URL and SP metadata for SAML. They’re also on the provider’s Setup tab.

Verify a domain

  1. Open the provider under IAM > Directory and select the Domain verification tab.

  2. At your DNS host, publish a TXT record for each domain the console lists, with its Name and the Value:

    Type Name Value
    TXT _better-auth-token-sso_k3f9a0x2m7qp.example.com The value the console shows

    The name is _better-auth-token-, the provider ID, a dot and the domain. Every domain of the provider uses the same value.

  3. Once the records are published, select Verify domain.

Every listed domain must have a matching TXT record. If one doesn’t, verification fails with No matching TXT record found for <domain> yet and no domain is verified. DNS changes can take time to be visible; select Verify domain again later. If the console says the verification token expired, delete the provider and add it again.

Sign in with SSO

People sign in at https://login.ezghcloud.com/sign-in/sso with their work email address, or select Sign in with SSO on the sign-in page. Someone who isn’t in your organization yet joins it the first time they sign in. Signing in is refused when:

  • Their account already belongs to another organization.
  • An administrator removed them from your organization. They can sign in with SSO again once they’re invited back.
  • SCIM is on and your identity provider hasn’t provisioned them.
  • Your identity provider suspended their account over SCIM.

Group mapping

Group mapping puts people in your organization’s groups based on the groups your identity provider sends.

  • Groups claim or attribute names the OIDC claim or SAML attribute that lists a person’s groups. The default is groups.
  • Each mapping pairs a group name at your identity provider with a group in your organization. Map everyone to a group adds everyone who signs in through the provider to a group.
  • On every sign-in, memberships from the mapping are added when the identity provider lists the group, and removed when it no longer does. Memberships added by hand stay.
  • Without a mapping, people join with no access until someone adds them to a group or attaches policies to them.
  • While SCIM is on, sign-in doesn’t change group memberships. SCIM manages provisioned groups instead.

To change the mapping, open the provider’s Group mapping tab and select Edit mapping. Changes apply from each person’s next sign-in.

Delete an identity provider

Open the provider under IAM > Directory, select Delete, and confirm. People in its domains can no longer sign in with SSO. Their accounts and group memberships stay. Its domains are no longer verified unless another provider lists them, so SCIM stops provisioning people in them.

Limits

Limit Value
Email domains One or more per provider, such as example.com. You can’t change a provider’s domains; delete it and add it again.
Identity providers added by one user 10
Identity provider URLs Public https URLs
SAML metadata 102,400 bytes
Group mappings per provider 100
Group name at your identity provider 256 characters
Groups claim or attribute 256 characters: letters, digits, _, :, /, . and -
Navigation

Type to search…

↑↓ navigate↵ selectEsc close